CVE-2010-3116

HIGH

Description

Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.

References

http://code.google.com/p/chromium/issues/detail?id=50515

http://code.google.com/p/chromium/issues/detail?id=51835

http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html

http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html

http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html

http://secunia.com/advisories/41856

http://secunia.com/advisories/42314

http://secunia.com/advisories/43068

http://secunia.com/advisories/43086

http://support.apple.com/kb/HT4455

http://support.apple.com/kb/HT4456

http://www.mandriva.com/security/advisories?name=MDVSA-2011:039

http://www.redhat.com/support/errata/RHSA-2011-0177.html

http://www.securityfocus.com/bid/44200

http://www.ubuntu.com/usn/USN-1006-1

http://www.vupen.com/english/advisories/2010/2722

http://www.vupen.com/english/advisories/2010/3046

http://www.vupen.com/english/advisories/2011/0212

http://www.vupen.com/english/advisories/2011/0216

http://www.vupen.com/english/advisories/2011/0552

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11909

Details

Source: MITRE

Published: 2010-08-24

Updated: 2020-08-04

Type: CWE-416

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
75629openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
68187Oracle Linux 6 : webkitgtk (ELSA-2011-0177)NessusOracle Linux Local Security Checks
critical
60943Scientific Linux Security Update : webkitgtk on SL6.x i386/x86_64NessusScientific Linux Local Security Checks
critical
53764openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
52523Mandriva Linux Security Advisory : webkit (MDVSA-2011:039)NessusMandriva Local Security Checks
critical
51672RHEL 6 : webkitgtk (RHSA-2011:0177)NessusRed Hat Local Security Checks
critical
5715Apple iOS < 4.2 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
critical
50654Safari < 5.0.3 Multiple VulnerabilitiesNessusWindows
high
50653Mac OS X : Apple Safari < 5.0.3 / 4.1.3NessusMacOS X Local Security Checks
high
50075FreeBSD : Webkit-gtk2 -- Multiple Vulnabilities (e5090d2a-dbbe-11df-82f8-0015f2db7bde)NessusFreeBSD Local Security Checks
critical
50046Ubuntu 9.10 / 10.04 LTS / 10.10 : webkit vulnerabilities (USN-1006-1)NessusUbuntu Local Security Checks
critical
50034Fedora 12 : webkitgtk-1.2.5-1.fc12 (2010-15982)NessusFedora Local Security Checks
critical
50030Fedora 13 : webkitgtk-1.2.5-1.fc13 (2010-15957)NessusFedora Local Security Checks
critical
801005Safari < 4.1.3 / 5.0.3 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
5711Safari < 4.1.3 / 5.0.3 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
800956Google Chrome < 5.0.375.127 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
5644Google Chrome < 5.0.375.127 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
48383Google Chrome < 5.0.375.127 Multiple VulnerabilitiesNessusWindows
high